🏷️
🌐

Encode User Content for Web Display

Prevent XSS attacks by encoding user-generated content before rendering it in HTML pages.

Non é necesario iniciar sesión
Output:
Examples:
Plain text / HTML
Encoded HTML
Output will appear here…
Common HTML entities reference
&&
<&lt;
>&gt;
"&quot;
'&#39;
·&nbsp;
©&copy;
®&reg;
&trade;
&euro;
&mdash;
&hellip;

Web tips

🛡️

Never render user-provided text directly in HTML without encoding. A user could inject <script> tags causing XSS attacks.

🔒

Encoding < as &lt; and > as &gt; turns any HTML tags in user input into plain visible text, not executable markup.

💡

Most server-side frameworks (Django, Rails, Laravel) auto-encode template variables. This tool is for manual encoding or debugging.

🔍

Paste suspicious user input here to inspect what HTML entities it contains before adding it to your codebase or database.

Como funciona

1
Entra
Enter your data into the tool above. Everything stays local to your browser.
2
Proceso
The tool processes your data instantly in your browser using JavaScript. No server, no waiting.
3
Descargar
Get your result instantly. Nothing is stored after you leave the page — complete privacy.

Por que usar o noso?

Completamente gratuíto, sen custos ocultos, nunca
Non se precisa ningunha conta, correo electrónico ou inicio de sesión
Os ficheiros nunca saen do teu dispositivo
Non hai límites de tamaño de ficheiro
Non hai marcas de auga en ningunha saída

Also check out…

Preguntas frecuentes